May 2020
Intermediate to advanced
544 pages
12h 57m
English
In a number of web applications, the developer introduces some custom HTTP headers that are then parsed when a request is processed. From generating a user-specific token to allowing access control through such custom headers, these headers have a different level of functionality altogether. In such scenarios, sometimes, the developer forgets to sanitize the user input, which, in turn, could become a target for exploitation. Let's see how we can fuzz custom headers using Wfuzz, ffuf, and Burp Suite.
Read now
Unlock full access